CPA · Question 31 · Area III: SOC Engagements
A service organization's system description includes controls performed by a subservice organization (e.g., a data center). The service auditor decides to use the 'carve-out' method. What does this imply for the service auditor's report?
Answer options:
The service auditor must test the controls at the subservice organization.
The subservice organization's controls are completely ignored and not mentioned.
The service auditor's opinion does not extend to the controls at the subservice organization.
The service auditor issues a qualified opinion due to scope limitation.
82 questions · hints · full answers · grading